Masking the GLP Lattice-Based Signature Scheme at Any Order

被引:28
|
作者
Barthe, Gilles [1 ]
Belaid, Sonia [2 ]
Espitau, Thomas [3 ]
Fouque, Pierre-Alain [4 ]
Gregoire, Benjamin [5 ]
Rossi, Melissa [6 ,7 ]
Tibouchi, Mehdi [8 ]
机构
[1] IMDEA Software Inst, Madrid, Spain
[2] CryptoExperts, Paris, France
[3] UPMC, Paris, France
[4] Univ Rennes, Rennes, France
[5] Inria Sophia Antipolis, Sophia Antipolis, France
[6] Thales, Paris, France
[7] PSL Res Univ, INRIA, CNRS, Dept Informat,Ecole Normale Super Paris, Paris, France
[8] NTT Secure Platform Labs, Tokyo, Japan
基金
欧盟地平线“2020”;
关键词
Side-channel; Masking; GLP lattice-based signature; FIAT-SHAMIR;
D O I
10.1007/978-3-319-78375-8_12
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Recently, numerous physical attacks have been demonstrated against lattice-based schemes, often exploiting their unique properties such as the reliance on Gaussian distributions, rejection sampling and FFT-based polynomial multiplication. As the call for concrete implementations and deployment of postquantum cryptography becomes more pressing, protecting against those attacks is an important problem. However, few countermeasures have been proposed so far. In particular, masking has been applied to the decryption procedure of some lattice-based encryption schemes, but the much more difficult case of signatures (which are highly non-linear and typically involve randomness) has not been considered until now. In this paper, we describe the first masked implementation of a lattice-based signature scheme. Since masking Gaussian sampling and other procedures involving contrived probability distribution would be prohibitively inefficient, we focus on the GLP scheme of Guneysu, Lyubashevsky and Poppelmann (CHES 2012). We show how to provably mask it in the Ishai-Sahai-Wagner model (CRYPTO 2003) at any order in a relatively efficient manner, using extensions of the techniques of Coron et al. for converting between arithmetic and Boolean masking. Our proof relies on a mild generalization of probing security that supports the notion of public outputs. We also provide a proof-of-concept implementation to assess the efficiency of the proposed countermeasure.
引用
收藏
页码:354 / 384
页数:31
相关论文
共 50 条
  • [21] Threshold Lattice-Based Signature Scheme for Authentication by Wearable Devices
    Leevik, Anton
    Davydov, Vadim
    Bezzateev, Sergey
    CRYPTOGRAPHY, 2023, 7 (03)
  • [22] Practical Lattice-Based Cryptography: A Signature Scheme for Embedded Systems
    Gueneysu, Tim
    Lyubashevsky, Vadim
    Poeppelmann, Thomas
    CRYPTOGRAPHIC HARDWARE AND EMBEDDED SYSTEMS - CHES 2012, 2012, 7428 : 530 - 547
  • [23] DiLizium: A Two-Party Lattice-Based Signature Scheme
    Vakarjuk, Jelizaveta
    Snetkov, Nikita
    Willemson, Jan
    ENTROPY, 2021, 23 (08)
  • [24] Lattice-based group signature scheme without random oracle
    Preethi, Thakkalapally
    Amberker, B. B.
    INFORMATION SECURITY JOURNAL, 2020, 29 (06): : 366 - 381
  • [25] Lattice-based Proxy Signature Scheme with Reject Sampling Method
    Jiang, Zoe L.
    Liang, Yudong
    Liu, Zechao
    Wang, Xuan
    2017 INTERNATIONAL CONFERENCE ON SECURITY, PATTERN ANALYSIS, AND CYBERNETICS (SPAC), 2017, : 558 - 563
  • [26] A Lattice-Based Unordered Aggregate Signature Scheme Based on the Intersection Method
    Lu, Xiuhua
    Yin, Wei
    Wen, Qiaoyan
    Jin, Zhengping
    Li, Wenmin
    IEEE ACCESS, 2018, 6 : 33986 - 33994
  • [27] A New Lattice-Based Threshold Attribute-Based Signature Scheme
    Wang, Qingbin
    Chen, Shaozhen
    Ge, Aijun
    INFORMATION SECURITY PRACTICE AND EXPERIENCE, ISPEC 2015, 2015, 9065 : 406 - 420
  • [28] High-order Polynomial Comparison and Masking Lattice-based Encryption
    Coron, Jean-Sébastien
    Gérard, François
    Montoya, Simon
    Zeitoun, Rina
    IACR Transactions on Cryptographic Hardware and Embedded Systems, 2022, 2023 (01): : 153 - 192
  • [29] A Lattice-Based Redactable Signature Scheme using Cryptographic Accumulators for Trees
    Zhao, Yong
    Yang, Shaojun
    Wu, Wei
    Huang, Xinyi
    COMPUTER JOURNAL, 2023, 66 (12): : 2961 - 2973
  • [30] A Lattice-Based Group Signature Scheme with Message-Dependent Opening
    Libert, Benoit
    Mouhartem, Fabrice
    Khoa Nguyen
    APPLIED CRYPTOGRAPHY AND NETWORK SECURITY, ACNS 2016, 2016, 9696 : 137 - 155